Skip to content

Update Go to 1.16.10#3357

Merged
thaJeztah merged 1 commit intodocker:masterfrom
thaJeztah:bump_go_1.16.10
Nov 12, 2021
Merged

Update Go to 1.16.10#3357
thaJeztah merged 1 commit intodocker:masterfrom
thaJeztah:bump_go_1.16.10

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

  • archive/zip: don't panic on (*Reader).Open
    Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
    to panic by an attacker providing either a crafted ZIP archive containing
    completely invalid names or an empty filename argument.
    Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
    Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
    golang.org/issue/48085.
  • debug/macho: invalid dynamic symbol table command can cause panic
    Malformed binaries parsed using Open or OpenFat can cause a panic when calling
    ImportedSymbols, due to an out-of-bounds slice operation.
    Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
    issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

- archive/zip: don't panic on (*Reader).Open
  Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
  to panic by an attacker providing either a crafted ZIP archive containing
  completely invalid names or an empty filename argument.
  Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
  Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
  golang.org/issue/48085.
- debug/macho: invalid dynamic symbol table command can cause panic
  Malformed binaries parsed using Open or OpenFat can cause a panic when calling
  ImportedSymbols, due to an out-of-bounds slice operation.
  Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
  issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@codecov-commenter
Copy link
Copy Markdown

Codecov Report

Merging #3357 (e285f15) into master (3fb4fb8) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##           master    #3357   +/-   ##
=======================================
  Coverage   58.02%   58.02%           
=======================================
  Files         302      302           
  Lines       21761    21761           
=======================================
  Hits        12626    12626           
  Misses       8214     8214           
  Partials      921      921           

@thaJeztah
Copy link
Copy Markdown
Member Author

Copy link
Copy Markdown
Member

@mat007 mat007 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good!

@thaJeztah
Copy link
Copy Markdown
Member Author

let me bring this one in; thanks!

@thaJeztah thaJeztah merged commit b0343d9 into docker:master Nov 12, 2021
@thaJeztah thaJeztah deleted the bump_go_1.16.10 branch November 12, 2021 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants